Small software shop? The Cyber Resilience Act in 5 minutes.
8 August 2026 · 2 min read · by Admin
Most explanations of the EU Cyber Resilience Act are written for lawyers, or designed to scare you into buying something. Here's the plain version, for someone who runs or builds at a small software company and has ten minutes, tops.
What it is
The CRA is an EU law setting baseline cybersecurity rules for "products with digital elements" (software, firmware, connected devices) sold in the EU. The core idea: if you ship it, you're responsible for it being reasonably secure, for knowing what's in it, and for dealing with vulnerabilities over its life.
Does it apply to you?
If you sell or make software that runs in the EU, probably yes. There's no exemption for being small, a two-person shop is in scope the same way a multinational is. (Pure cloud SaaS is a contested edge case that leans toward other rules; anything a customer installs or runs is squarely in.)
The two dates that matter
- 11 September 2026 - you must report actively exploited vulnerabilities in your products to the authorities within 24 hours of becoming aware. (Micro and small companies can't be fined for missing this deadline, but the duty still applies, and you can't report what you can't see.)
- 11 December 2027 - the full rules land: a proper SBOM, secure-by-design practices, CE marking, technical documentation. These carry real penalties, with no small-company pass.
What to actually do
You don't need to panic, and you don't need a consultant yet. You need four small things:
- Commit your lockfiles. If your project's exact dependency versions aren't pinned in version control, fix that today. Everything else builds on it.
- Produce an SBOM for one product. The first one is uncomfortable; that's the point.
- Check yourself against the exploited-vulnerability list. CISA's KEV catalogue is public. If anything you ship is on it, you've just rehearsed the September deadline.
- Decide who's responsible. The clock starts when someone becomes "aware". Someone at your company needs to be that person.
That's it. Four steps, none of them expensive. Do them before a customer or an auditor asks, because that's when you'll wish you had.